Data Processing Agreement
Version 2026-05-22 · Effective: Pending
Draft document
This document is being finalised ahead of general availability. The section structure below is provisional and not yet binding. Final wording will be published before customer onboarding.
How NutriCare processes personal and health information on a facility’s behalf. Incorporated into the Terms of Service.
Roles
The customer is the controlling entity for resident data; NutriCare processes that data only on the customer’s documented instructions.
Scope and nature of processing
The categories of data, the categories of data subject (residents, staff, family), and the purposes of processing.
Sensitive information and consent
Resident health information is sensitive information under the Privacy Act. The customer warrants it has the authority and consents required to provide that information to NutriCare, including for AI features.
Sub-processors
The published sub-processor list is incorporated by reference. NutriCare gives notice before adding a new sub-processor.
Cross-border disclosure
Most data resides in Australia. AI features may disclose data to Anthropic in the United States; this is controlled by an organisation-level opt-out.
Security measures
The technical and organisational security measures NutriCare applies, drawn from its security and compliance register.
Data breach notification
NutriCare notifies the customer without undue delay of a data breach affecting its data, so the customer can meet its Notifiable Data Breaches obligations.
Data subject requests
NutriCare assists the customer in responding to resident access and correction requests.
Return and deletion of data
Export and deletion of customer data on termination, accounting for aged-care record-retention requirements.
Audit
The customer’s rights to review NutriCare’s security posture.
Questions about this document? Contact hello@day-zero.com.au.